Subject: Re: PAM and OpenSSH
To: Jason Thorpe <thorpej@shagadelic.org>
From: Roland Dowdeswell <elric@imrryr.org>
List: tech-userlevel
Date: 01/26/2005 12:58:09
On 1106759066 seconds since the Beginning of the UNIX epoch
Jason Thorpe wrote:
>

>The complication here is that the SSH protocol itself has provisions 
>for the Kerberos protocol.  I seem to recall that in SSHv2, the 
>Kerberos (GSSAPI, really) credentials are used for transport re-keying, 
>as well.

Actually, there is old fashioned krb5 support in protocol 2 as well
as the GSSAPI support which we'll need to pull back in, also.  So,
we'll need to support 3 Kerberos authentication methods.

--
    Roland Dowdeswell                      http://www.Imrryr.ORG/~elric/